Foundational certification covering cloud concepts, Azure architecture and services, and Azure management and governance.
Free sample questions
No account needed. Every question has a worked explanation, just like the full bank.
lock_openFree sampleDescribe Cloud Conceptseasy
A new cloud customer wants to know which responsibility they retain no matter whether they adopt IaaS, PaaS, or SaaS. Which set always stays with the customer?
- ATheir stored data and their accounts and identitiescheck_circle Correct
- BThe physical datacentre and the racks within it
- CThe physical network that links the servers
- DThe physical hosts that run the workloads
Your data and your identities are always your responsibility in the cloud, whatever the service model. Across the shared responsibility model, data or information stored in the cloud and the accounts and identities of people, services, and devices are listed as always the customer's, irrespective of whether the service is IaaS, PaaS, or SaaS, because only the customer can govern who and what they trust.
Why A is correct: Correct. Across the shared responsibility model, data or information stored in the cloud and the accounts and identities of people, services, and devices are listed as always the customer's, irrespective of whether the service is IaaS, PaaS, or SaaS, because only the customer can govern who and what they trust.
Why B is wrong: The physical datacentre is real and tempting because the customer pays for capacity, but the model lists it as always the provider's responsibility, never the customer's.
Why C is wrong: The physical network is a genuine shared-responsibility item, yet the model assigns the physical network to the provider in every service model, not the customer.
Why D is wrong: Physical hosts feel customer-adjacent because workloads run on them, but the model places the physical hosts permanently with the provider regardless of service type.
lock_openFree sampleDescribe Azure Management and Governanceeasy
An organisation needs a single unified view to govern its data wherever it lives, spanning on-premises stores, multiple clouds, and SaaS applications, with automated data discovery, sensitive-data classification, and end-to-end data lineage. Which tool provides this?
- AAzure Policy, which governs Azure resource configuration, not data
- BMicrosoft Purview, which governs the data estate across all sourcescheck_circle Correct
- CMicrosoft Defender for Cloud, which manages cloud security posture
- DAzure Monitor, which collects operational telemetry from your resources
Microsoft Purview governs the data estate across on-premises, multicloud, and SaaS sources with discovery, classification, and lineage. Microsoft Purview is a family of data governance solutions that brings insights about on-premises, multicloud, and SaaS data together into one view, building a current map of the data estate that includes classification and end-to-end lineage so sensitive data can be located and managed at scale.
Why A is wrong: Azure Policy enforces rules on Azure resource configurations, which is a governance service, but it operates on resource settings rather than mapping and classifying the data estate, so it does not give a unified view of data.
Why B is correct: Correct. Microsoft Purview is a family of data governance solutions that brings insights about on-premises, multicloud, and SaaS data together into one view, building a current map of the data estate that includes classification and end-to-end lineage so sensitive data can be located and managed at scale.
Why C is wrong: Microsoft Defender for Cloud assesses security posture and surfaces protection recommendations, which is appealing for oversight, but its focus is security rather than discovering and classifying data across sources.
Why D is wrong: Azure Monitor gathers metrics and logs about how resources perform, which is broad visibility, but it covers operational telemetry rather than cataloguing, classifying, or tracing the lineage of data.
lock_openFree sampleDescribe Azure Architecture and Servicesmedium
Inside a single Azure region, a designer wants the construct made up of one or more physically separate datacentres that each have independent power, cooling, and networking and that act as an isolation boundary. Which construct fits?
- AAn availability zone, a separate datacentre that is an isolation boundarycheck_circle Correct
- BA region pair set up across two regions in one geography
- CA sovereign region isolated for legal or compliance reasons
- DA resource group that logically groups related Azure resources
An availability zone is a physically separate datacentre within a region acting as an isolation boundary. An availability zone is defined as one or more physically separate datacentres within a region, each equipped with independent power, cooling, and networking, deliberately set up as an isolation boundary so that one zone failing leaves the others working.
Why A is correct: Correct. An availability zone is defined as one or more physically separate datacentres within a region, each equipped with independent power, cooling, and networking, deliberately set up as an isolation boundary so that one zone failing leaves the others working.
Why B is wrong: A region pair spans two distinct regions for cross-region recovery, so it operates above the region level rather than as a separate datacentre inside one region, which is what the stem requires.
Why C is wrong: A sovereign region is an isolated instance of Azure for compliance purposes, not a separate datacentre within a normal region acting as a resiliency isolation boundary, so it does not fit.
Why D is wrong: A resource group is a logical management container with no physical datacentre or independent power meaning, so it cannot be the isolation boundary made of separate datacentres.
More free AZ-900 practice questions with worked answersExamworthy is not affiliated with or endorsed by Microsoft. All questions are original, blueprint-aligned practice material. We never reproduce live exam items. AZ-900 and related marks belong to their respective owners.